# Juniper Firewall Analyzer · SRX & Junos

> Analyze Juniper SRX (Junos OS) zone-based security policies, NAT, the address book, security zones, and IPsec VPNs in one self-hosted dashboard. Configuration state, not logs.

Last updated: July 2026

Reads Juniper SRX (Junos OS) configuration state directly, read-only:

- **Zone-based security policies**: browse and search Junos security policies by from-zone, to-zone, source, destination, application, and action across the whole SRX estate.
- **Source, destination & static NAT**: Junos NAT rule sets with address-book entries resolved to real prefixes.
- **Address book, resolved**: address sets and application sets expanded recursively, so you see "HTTPS (tcp/443)" and the real prefixes behind every group.
- **Security zones & interfaces**: zone-to-interface bindings in one view.
- **IPsec VPN visibility**: IKE gateways, IPsec VPNs, and the security policies that permit tunnel traffic.
- **Change tracking**: every Junos configuration change detected, diffed, and attributed to the admin who committed it.

It is a configuration analyzer, not a log analyzer, and it sits in the same dashboard as your Palo Alto, FortiGate, and Cisco estate.

## SAMURAI vs single-vendor SRX managers

| | SAMURAI | Single-vendor managers |
|---|---|---|
| Scope | Juniper SRX plus Palo Alto, FortiGate, Cisco FMC, routers, switches, and ACI in one multi-vendor view | Juniper-only policy management |
| Deployment | Single Docker container, self-hosted, air-gap friendly, serving data in about five minutes | Dedicated management appliance or VM |
| Analysis | Effective access, shadowed/redundant/overly-broad detection, and per-rule risk scoring across vendors | Policy authoring and push within one vendor |
| Change visibility | Cross-vendor change timeline with commit attribution | Juniper commit history in isolation |

## Frequently asked questions

### Which Juniper devices does SAMURAI support?

Juniper SRX series firewalls running Junos OS. SAMURAI reads their configuration state, zone-based security policies, NAT, address book, applications, security zones, and IPsec VPNs, alongside your Palo Alto, FortiGate, and Cisco FMC firewalls.

### Is SAMURAI a Juniper log analyzer?

No. SAMURAI is a Juniper configuration analyzer, not a log analyzer. It reads policy and configuration state from each SRX rather than parsing traffic logs or syslog, so you analyze the rules themselves and every change to them.

### How does SAMURAI read the SRX configuration?

Over Junos native interfaces, reading the structured configuration the device already exposes, read-only. SAMURAI does not modify or push Junos configuration; it syncs state continuously and diffs it.

### Does it work across Juniper and other vendors at once?

Yes, that is the point. SRX policies sit in the same searchable dashboard and change timeline as Palo Alto, FortiGate, and Cisco FMC, with path tracing across the routers, switches, and ACI fabrics between them.

### Is there a free option?

Yes. A free test license ships with the SAMURAI Docker image on Docker Hub, no email required. Production use is licensed per deployment, sized by device count.

---

Canonical page: https://nometa.az/en/juniper-firewall-analyzer/
Part of SAMURAI, a self-hosted, multi-vendor network monitoring & security platform. Overview: https://nometa.az/llms.txt
Contact: info@nometa.az · Docker Hub: https://hub.docker.com/r/beyrak44/samurai
